Privacy Policy
Plain-language explanation of what TempleOS collects on behalf of temples, how it's used, and the choices devotees and temple administrators have — including for WhatsApp messaging.
TempleOS ("TempleOS", "we", "us") is a software-as-a-service platform that helps temples manage their temple profile, devotee registration, seva bookings, donations, events, a WhatsApp chatbot, and broadcast announcements from a single dashboard. This Privacy Policy explains what personal information we collect, why we collect it, and the choices available to temple administrators (who manage a temple's account) and devotees (who interact with a temple through TempleOS, most commonly via WhatsApp).
This policy is effective as of July 20, 2026 and was last updated on July 20, 2026.
Who this policy applies to
This policy applies to anyone whose information is processed through TempleOS: temple administrators and staff who use the dashboard, and devotees who register with a temple, book sevas, make donations, or receive WhatsApp messages from a temple using TempleOS.
Our role: software provider, not the temple
TempleOS is a multi-tenant platform. Each temple operates its own independent account, connects its own Meta WhatsApp Business Account, and controls its own devotee records, seva schedules, pricing, and announcements. In privacy-law terms, each temple is the data controller for its devotees' information, and TempleOS is the data processor— we provide and operate the software that stores and processes that information on the temple's behalf, under the temple's instructions. See Temple Responsibility for Devotee Data and TempleOS's Role as Software Provider below for how this division of responsibility works in practice.
When a temple signs up for TempleOS, we collect information about the temple and the people who administer it:
- Admin account details: name, phone number, and email address of temple administrators and staff granted dashboard access.
- Temple profile information: temple name, address, deity/tradition details, logo, description, and other content the temple chooses to publish.
- Seva and event configuration: seva names, schedules, pricing, capacity, and event details entered by the temple.
- WhatsApp Business Account details: the WhatsApp Business Account ID, phone number ID, and related configuration provided when a temple connects its account through Meta Embedded Signup (see WhatsApp Business Platform Integration).
- Role and permission data: which staff members have which level of access within the dashboard.
- Technical information: device, browser, and access-log information (such as IP address and timestamps) generated when administrators use the dashboard.
On behalf of the temple, TempleOS may store the following information about devotees:
- Identity information: devotee name, phone number, and WhatsApp number.
- Optional contact details: email address, where provided.
- Transaction history:donation history and seva booking history associated with the devotee's profile at a given temple.
- Preferences: event and announcement preferences, language preference, and WhatsApp messaging consent status.
- WhatsApp conversation data:messages exchanged with a temple's WhatsApp chatbot, including delivery and read status, to the extent needed to provide booking confirmations, receipts, and support.
- Technical information:device and browser information collected automatically if a devotee uses the temple's web-based booking or donation pages.
We do not collect government identification numbers, and we do not treat religious affiliation with a particular temple as sensitive personal data requiring special handling beyond what is described in this policy.
Information collected through TempleOS is used to:
- Operate temple profiles, devotee registration, and the temple administration dashboard.
- Process and confirm seva bookings and record donations.
- Send event reminders, temple announcements, booking confirmations, and donation receipts via WhatsApp or email.
- Power the temple's WhatsApp chatbot for FAQs, bookings, and support requests.
- Maintain accurate records for temple administrators, including reporting and reconciliation.
- Maintain the security, reliability, and performance of the platform, and prevent fraud or abuse.
- Comply with applicable legal, tax, and regulatory obligations.
We do not sell personal information, and we do not use devotee data for advertising or share it with unrelated third parties for their own marketing purposes.
TempleOS is built on Meta's WhatsApp Business Platform (WhatsApp Cloud API). This lets each temple run its own WhatsApp presence for devotee communication, while TempleOS provides the underlying software and infrastructure.
Meta Embedded Signup
Temples connect their own WhatsApp Business Account to TempleOS using Meta Embedded Signup, Meta's official onboarding flow. Through this flow, a temple grants TempleOS — acting as a Meta Tech Provider — permission to send and receive WhatsApp messages on the temple's behalf, using a single platform-level system user token. No temple's WhatsApp credentials or per-tenant access tokens are shared between temples, and TempleOS does not gain access to a temple's broader Meta Business Manager beyond what Embedded Signup explicitly grants.
How the WhatsApp Cloud API is used
- Delivering event reminders, announcements, booking confirmations, and donation receipts that a devotee has opted in to receive.
- Operating each temple's WhatsApp chatbot for common devotee questions and requests.
- Recording delivery and read receipts so temples can see whether a message reached a devotee.
Message content and delivery metadata are processed by Meta in the course of delivering WhatsApp messages, in accordance with Meta's own privacy practices, in addition to this policy.
WhatsApp messaging through TempleOS is strictly opt-in. In practice, this means:
- A devotee must explicitly opt in — typically by registering their WhatsApp number with a temple and agreeing to receive messages — before they are sent event reminders, temple announcements, booking confirmations, or donation receipts.
- Consent is recorded per devotee, per temple, and is never assumed just because a phone number exists elsewhere in our systems.
- A devotee may opt out at any time by replying "STOP" (or another supported opt-out keyword configured by the temple) to any WhatsApp message, or by asking the temple administrator to remove them from messaging lists in the dashboard.
- Once a devotee opts out, TempleOS stops sending non-essential WhatsApp messages to that number until they opt in again.
- Message delivery depends on Meta's WhatsApp infrastructure and the devotee's own carrier or device, and may occasionally be delayed or temporarily unavailable for reasons outside TempleOS's control.
- TempleOS and every temple using the platform are required to comply with Meta's WhatsApp Business Messaging Policy, which prohibits unsolicited or unrelated marketing messages over this channel.
Donations made through TempleOS are processed by secure, PCI-DSS compliant third-party payment gateways. TempleOS never stores card numbers, CVVs, UPI PINs, or banking credentials. We store only the information necessary to record the transaction and generate a receipt: donation amount, currency, date, payment status, and a reference ID linking back to the payment gateway's own transaction record.
Because payment processing is handled by the gateway rather than by TempleOS directly, any issue with a card, bank transfer, or UPI payment (such as a declined transaction or a delay in settlement) is subject to the payment gateway's own terms and support process.
The TempleOS dashboard uses strictly necessary cookies to keep administrators signed in (session cookies) and to remember display preferences such as language and light/dark theme. These cookies do not track devotees across other websites and are not used for advertising.
Where TempleOS uses basic, privacy-respecting analytics to understand dashboard usage and improve the product, this data is aggregated and is not used to build advertising profiles of devotees or temple staff. We do not currently use third-party advertising or cross-site tracking cookies.
Retention
Devotee, donation, and booking records are retained for as long as the temple maintains an active account on TempleOS, and thereafter for as long as reasonably necessary to comply with legal, accounting, or tax reporting obligations (for example, donation records that a temple is required to retain for tax purposes).
Deletion requests
A devotee who wants their information deleted should first contact the relevant temple administrator, since the temple controls its own devotee records. A temple administrator may request deletion or export of a devotee's data directly within the dashboard, or by contacting us at privacy@trytempleos.com. Deletion requests are honored subject to any records a temple is legally required to keep — where full deletion isn't possible, we will anonymize or restrict further use of the data instead.
We apply industry-standard safeguards to protect information stored in TempleOS, including:
- Encrypted data transmission (HTTPS/TLS) between devices, our servers, and connected third-party services.
- Encrypted database connections and access-controlled infrastructure.
- Role-based permissions within each temple's dashboard, so staff only see what their role permits.
- Passwordless, OTP-based authentication for administrators, reducing risks associated with reused or weak passwords.
- Isolation between tenants, so one temple's data is not accessible to another temple's administrators.
No method of transmission or storage is 100% secure. While we work hard to protect information under our control, we cannot guarantee absolute security, and we encourage administrators to safeguard their own login access.
TempleOS and the third-party providers we rely on (such as cloud hosting, database, and messaging infrastructure) may process and store data in countries other than the one where a temple or devotee is located. Where this occurs, we take reasonable steps to ensure that any cross-border transfer is protected by appropriate contractual or technical safeguards consistent with applicable data protection law.
TempleOS relies on the following categories of third-party services to operate:
- Meta WhatsApp Business Platform: used to send and receive WhatsApp messages, as described in WhatsApp Business Platform Integration.
- Payment gateways: used to process donations securely, as described in Donations & Payment Processing.
- Firebase (Google): used for secure phone-number authentication of temple administrators.
- Cloud hosting and database providers: used to host the application and store data securely.
These providers only receive the information necessary to perform their function and are contractually bound to appropriate confidentiality and security obligations.
Each temple using TempleOS is responsible for the devotee data it collects, including:
- Obtaining valid consent from devotees before collecting their information or messaging them on WhatsApp.
- Ensuring the accuracy of devotee records, seva schedules, pricing, and announcements it publishes.
- Responding to devotee requests to access, correct, or delete their information.
- Using devotee data only for legitimate temple purposes, not for unrelated resale or disclosure.
- Complying with any additional local laws that apply to how the temple collects or uses personal data.
TempleOS does not verify the accuracy of information a temple publishes about itself, its sevas, or its events — that responsibility rests with the temple administrator who entered it.
TempleOS is the software provider that makes temple management possible. Our responsibility is to:
- Securely host and process data on behalf of temples, in line with this Privacy Policy.
- Provide the technical infrastructure connecting temples to Meta's WhatsApp Business Platform and to payment gateways.
- Maintain reasonable security and availability of the platform.
- Support temples and devotees with data access, correction, and deletion requests routed through us.
TempleOS does not own, operate, or control any individual temple, and does not independently verify the religious, doctrinal, or factual accuracy of content a temple publishes. We are not responsible for a temple's own decisions about how it collects consent, sets seva pricing, or manages its devotee relationships, beyond providing the tools to do so responsibly.
Subject to applicable law, devotees and temple administrators may:
- Request access to the personal information held about them.
- Request correction of inaccurate or outdated information.
- Request deletion of their information, subject to legal retention requirements.
- Opt out of WhatsApp or other communications at any time.
- Request a copy of their donation or booking history in a portable format.
Requests should be directed to the relevant temple administrator in the first instance, or to us directly using the contact details below, and will be forwarded to the responsible temple where appropriate.
TempleOS is intended for use by temple administrators and adult devotees. We do not knowingly collect personal information directly from children under the age of 13 (or the relevant age of digital consent in the devotee's jurisdiction). Where a temple records a minor as a dependent family member for seva or event purposes, this information is provided and managed by a parent, guardian, or the temple administrator, not collected directly from the child. If we learn that a child's personal information has been collected without appropriate parental or guardian involvement, we will work with the relevant temple to delete it.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The "Last updated" date at the top of this page indicates when this policy was last revised, and the "Effective" date indicates when the current version took effect. Material changes will be communicated to temple administrators via the dashboard or email where reasonably possible. Continued use of TempleOS after a policy update constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy or how your information is handled, contact us at privacy@trytempleos.com.